CVE-2026-102278: Stack-Based Denial of Service via Uncontrolled Recursion in brace-expansion
Vulnerability ID: CVE-2026-102278
CVSS Score: 7.5
Published: 2026-09-29
A stack-based Denial of Service (DoS) vulnerability via uncontrolled recursion in the brace-expansion library prior to versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11 allows unauthenticated remote attackers to trigger native stack exhaustion, terminating the Node.js process via a crafted payload containing deeply nested brace groups.
TL;DR
Uncontrolled recursion in nested brace groups allows unauthenticated attackers to crash the Node.js process via a stack overflow using compact (~6KB) inputs.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-674
- Attack Vector: Network (Unauthenticated)
- CVSS: 7.5 (High)
- EPSS: 0.0035 (26th percentile)
- Impact: Denial of Service (Process Termination)
- Exploit Status: Proof-of-Concept
- KEV Status: Not Listed
Affected Systems
- Node.js applications processing untrusted shell-like patterns or glob vectors via brace-expansion.
- Libraries utilizing brace-expansion transitively, such as older versions of minimatch or glob parsers.
-
brace-expansion: < 1.1.20 (Fixed in:
1.1.20) -
brace-expansion: >= 2.0.0, < 2.1.6 (Fixed in:
2.1.6) -
brace-expansion: >= 3.0.0, < 3.0.8 (Fixed in:
3.0.8) -
brace-expansion: >= 4.0.0, < 5.0.11 (Fixed in:
5.0.11)
Code Analysis
Commit: 935d78f
Bound nesting recursion using EXPANSION_MAX_DEPTH in TypeScript module.
Commit: de84f14
Add maxDepth configuration and depth monitoring on nested expands for ESM.
Commit: 1efee7c
Implement recursion depths and legacy ES5 compatibility variables.
Exploit Details
- GitHub Advisory: Security advisory details containing vulnerability mechanics and reproduction methods.
Mitigation Strategies
- Upgrade dependency to patched versions across all active branches.
- Sanitize and restrict input pattern complexity at application entry points.
- Employ process managers (e.g., PM2) to ensure auto-restart capability upon crash events.
Remediation Steps:
- Identify vulnerable versions of brace-expansion using 'npm ls brace-expansion' or Software Composition Analysis.
- Force update of deep dependencies using package manager resolutions or overrides if transitive.
- In npm projects using version 5, execute: npm install brace-expansion@5.0.11
- Verify the application does not crash when supplied with deeply nested brace patterns.
References
Read the full report for CVE-2026-102278 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)